Loading market data...
← Back to CVE feed

CVE-2026-88792

HIGH CVSS 8.8 View on NVD ↗

Description

The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding or updating dictionary entries, allowing unauthenticated users to store arbitrary web scripts which will execute when a user views an affected entry.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Published: Sep 17, 2026 06:16 UTC Modified: Sep 17, 2026 13:16 UTC